HomeSecurityWells Fargo: Its customers targeted by phishing campaign!

Wells Fargo: Its customers targeted in phishing campaign!

Wells Fargo customers are being targeted by a phishing campaign that is “impersonating” security and directing potential victims to phishing sites using Calendar invitations. Wells Fargo is a multinational financial services provider with approximately 263,000 employees in 7,400 locations in 31 countries and territories. It serves one-third of all U.S. households and was ranked 30th in Fortune 2020among America’s largest companies. The phishing emails, which were discovered by researchers at email Abnormal Security earlier this month, have targeted more than 15,000 Wells Fargo customers so far, using attached files that contain events and prompt recipients to visit phishing sites.

alerts are used to boost the success rate of attacks

The attackers’ phishing emails warn potential victims that they need to update their security keys by following instructions included in an attached .ics calendar file, while claiming that doing so will prevent their accounts from being deleted. Specifically, Abnormal Security reports that the description of the incident includes a link to a Sharepoint page that directs users to click on another link to secure their account. This link leads to a fake phishing page, supposedly belonging to Wells Fargo. On this page, users are asked to enter sensitive information such as their username, password, PIN, and account numbers. The scammers behind this campaign are urging potential victims to open the calendar file on their phones so that they can take advantage of the fact that the event contained in the .ics file will be automatically added to the victims’ calendar. The victims’ calendar apps will then automatically display notifications, which the victims will likely click on, as the notifications are being sent to them by a trusted app. This is the main reason for the high success rate of these scams, and the attackers are estimated to be able to collect sensitive information from many more Wells Fargo customers.

Wells Fargo: Its customers targeted in phishing campaign!

The final phishing page that the Sharepoint redirect page takes victims to is a fake Wells Fargo login page, asking users to enter their credentials, account numbers, email addresses, passwords, and four-digit card number. If victims fall for the scam, enter their details, and click the “SUBMIT” button at the bottom of the page, the attackers will gain access to all the information they need to compromise their accounts, stealing the victims’ identities and money.

Wells Fargo: Its customers targeted in phishing campaign!

At this point, it is worth noting that bank customers have always been an attractive target for hackers. As Abnormal Security reports, financial institutions are always the main targets of hackers. Access to a user’s sensitive information would allow a hacker to steal the victim’s identity and subsequently the money in their bank account. Many of these companies have strict regulations and security to protect their users and their financial activities. However, hackers are constantly finding ways to compromise user accounts. Over the past week, security researchers at F5 Labs have identified ongoing attacks that aim to steal credentials from customers of dozens of US financial institutions by infecting them with Qbot banking trojan payloads. Among the list of banks whose customers were targeted by this Qbot campaign, researchers found Bank of America, Wells Fargo, JP Morgan, Citibank, Citizens, Capital One and FirstMerit Bank, while 36 different U.S. financial institutions and two banks in Canada and the Netherlands were also targeted. Two months ago, scammers also sent emails purporting to come from the U.S. Federal Reserve, luring recipients with offers of financial relief through the Payment Protection Program.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS